Skip to main content Scroll Top

When AI Becomes Your Shopping Agent: Rethinking Authority and Consumer Protection in the Age of Agentic AI

HeckelAI_July_Feyi Lari Williams_Image For Article

The past year has witnessed a noticeable shift in the trajectory of consumer artificial intelligence. The principal technology companies have been developing AI systems capable of acting on behalf of users.¹ We have examples in Google’s Gemini Spark, OpenAI’s operator and agent capabilities, and Anthropic’s continued expansion of Claude’s task execution capabilities. These systems move beyond simply generating information to searching, comparing, deciding and sometimes transacting.

The legal significance of this development was perhaps best illustrated by a pre-release version of Google’s Gemini application. Before the company’s I/O keynote, an onboarding screen reportedly informed users that Gemini Spark “may do things like share your info or make purchases without asking.”² Although that language was softened prior to release, with Google instead explaining that Spark is “designed to check with you before taking major actions”,³ the episode nevertheless highlighted an issue that extends well beyond Google’s own ecosystem.

As AI systems begin to conclude transactions on behalf of consumers, they inevitably enter territory long occupied by private law. In a way, this development is not novel. Contract law has never required parties to conclude contracts personally. Individuals routinely purchase property through estate agents, instruct travel agents to arrange holidays, appoint solicitors to negotiate settlements and authorise employees to conclude commercial transactions. Indeed, one of the defining characteristics of contract law is that it has always recognised that legally significant acts may be performed through intermediaries. Agency is therefore not an exception to contractual autonomy but one of its principal manifestations.

Nor would this be the first time that technological innovation has altered the mechanics of contract formation. Contract law has repeatedly adapted established principles of offer and acceptance to changing methods of communication. The postal rule developed for correspondence in Adams v Lindsell⁴ gave way to the receipt rule for instantaneous communications in Entores Ltd v Miles Far East Corporation,⁵ a principle later refined by the English House of Lords in Brinkibon Ltd v Stahag Stahl.⁶ The emergence of electronic commerce likewise prompted the adaptation of existing principles rather than their wholesale replacement.⁷ Each development required courts to consider how established principles should apply within changing commercial environments.

However, what distinguished these developments from the current phase of agentic AI is that with them, the underlying premise remained largely unchanged. Technology communicated, recorded or executed human decisions; it did not meaningfully participate in the process by which those decisions were formed. But unlike traditional automation, contemporary AI agents do not merely execute predetermined instructions. They are being designed to exercise judgement within parameters established by the user.⁸ A consumer may instruct an AI to ” purchase the best laptop under €900″, to ” book the cheapest direct train arriving before noon”, or to arrange accommodation that satisfies multiple competing preferences. The AI must interpret those instructions, identify relevant products, compare alternatives, prioritise competing objectives and ultimately determine which transaction should be concluded.

The central doctrinal difficulty is this setup is not only in identifying the intermediary, but identifying the source and scope of the authority under which it acts. Agency law has long distinguished between actual, implied and apparent authority, with each doctrine ultimately seeking to determine whether the acts of an intermediary should bind the principal.⁹ Those questions get much more complex where the intermediary derives its decision-making not from a discrete instruction, but from an evolving combination of user prompts, remembered preferences, contextual reasoning and probabilistic inference.

Human agents ordinarily derive their authority from identifiable manifestations of the principal’s intention. Those manifestations may be express or implied, but they remain capable of subsequent interpretation by a court. But the authority under which AI systems act may derive simultaneously from natural language instructions, accumulated interactions, inferred preferences and contextual reasoning.¹⁰ The practical consequence is that determining whether an AI has acted within the authority conferred by the user may become considerably more difficult than interpreting the mandate given to a human intermediary. The implications of this difficulty become particularly apparent when transactions go wrong.

Suppose a consumer asks an AI to purchase “the best available seats” for a concert, having repeatedly expressed in earlier interactions a preference for premium experiences over lower prices. The AI purchases VIP tickets that significantly exceed the consumer’s usual spending expectations. Or, after months of observing that a consumer consistently opts for subscription services to secure discounted pricing, the AI enrolls the consumer in a recurring subscription rather than purchasing a single item outright. In neither case has the AI necessarily failed to follow instructions. Rather, it has acted on an interpretation of authority constructed from a combination of the consumer’s immediate request, prior interactions and inferred preferences. Contract lawyers will immediately recognise familiar doctrinal questions. Did the intermediary exceed its authority? Was there a mistake? Which party should bear the resulting loss? Existing doctrine undoubtedly provides starting points for answering these questions. The more difficult issue is whether doctrines developed around human intermediaries allocate risk appropriately where the intermediary exercises computational rather than human judgement.

Consumer law presents a different, but no less significant, challenge. Whereas contract law is principally concerned with the existence and validity of agreement, consumer law is built around the quality of consumer decision-making. The Consumer Rights Directive, the Unfair Commercial Practices Directive and the Digital Content and Digital Services Directive all proceed from a common behavioural premise: consumers should receive sufficient information to make informed commercial decisions. Mandatory disclosures, transparency obligations and information duties all seek to improve the conditions under which consumers exercise their autonomy.

With agentic AI, the entity reading cancellation policies, comparing contractual terms, evaluating delivery conditions and assessing product reviews is the consumer’s AI agent. The protected party remains the consumer, but many of the cognitive processes that consumer law seeks to safeguard are delegated to software acting on the consumer’s behalf. So, if mandatory information has been disclosed to, analysed by and acted upon through an AI agent, has the underlying purpose of the disclosure obligation been fulfilled? More fundamentally, can a legal framework constructed around human information processing continue to operate unchanged where purchasing decisions are increasingly mediated through autonomous digital agents?

These questions should not be mistaken for claims that existing law has become obsolete. On the contrary, one of the enduring strengths of private law lies in the adaptability of its doctrines. Agency law has evolved alongside changing forms of commerce for centuries, while consumer law has repeatedly accommodated new methods of contracting. The challenge presented by agentic AI is that it exposes assumptions that have remained largely invisible precisely because they have never previously been challenged. Much of private law proceeds on the unstated premise that the intermediary exercising judgement on behalf of another is ultimately human. As AI systems increasingly search, compare, evaluate and contract on behalf of consumers, that assumption becomes progressively more difficult to maintain.

Whether Gemini Spark, OpenAI’s agents or Anthropic’s evolving ecosystem ultimately succeed commercially is secondary, as the broader trajectory is already apparent. Consumer AI is moving from assistance towards representation. As it does so, contract lawyers and consumer lawyers may find themselves returning to some of the oldest ones in private law, and yet again, finding ways to adapt them.

References

¹ OpenAI, Introducing Operator (23 January 2025) https://openai.com/index/introducing-operator/ , assessed on 18 July 2026 (describing Operator as “an agent that can go to the web to perform tasks for you” and noting its ability to browse, click and complete tasks independently);
² Josiah Motley, ‘Gemini Spark: Google’s 24/7 Cloud AI Agent Now Executes Tasks in Third-Party Apps’ TechTimes (25 May 2026) https://www.techtimes.com/articles/317144/20260525/gemini-spark-googles-24-7-cloud-ai-agent-now-executes-tasks-third-party-apps.htm accessed 10 July 2026.
³ Ibid
⁴ (1818) 1 B & Ald 681
⁵ [1955] 2 QB 327
⁶ [1983] 2 AC 34
⁷ UNCITRAL Model Law on Electronic Commerce 1996; Directive 2000/31/EC (E-Commerce Directive), particularly arts 9–11
⁸ OpenAI, Introducing Operator (23 January 2025) https://openai.com/index/introducing-operator/, assessed on 18 July 2026; Madhumita Murgia, ‘Anthropic’s New AI Model Can Control Your Computer’ Financial Times (22 October 2024), https://www.ft.com/content/f49aff66-79e8-437a-93c2-96f8116c1bc3, assessed on 18 July 2026
⁹ Peter Watts and FMB Reynolds (eds), Bowstead & Reynolds on Agency (23rd edn, Sweet & Maxwell 2024), Ch. 3; PECL Chapter 3; UNIDROIT Principles art 2.2.1.
¹⁰ OpenAI, Overview – OpenAI Agents SDK: Sessions (explaining that agents automatically maintain conversation history across runs), https://openai.github.io/openai-agents-python/sessions/, assessed on 18 July 2026; OpenAI, Agent Memory – OpenAI Agents SDK (explaining persistent memory that allows future runs to learn from prior interactions), https://openai.github.io/openai-agents-python/sandbox/memory/, assessed on 17 July 2026; Google Cloud, Core Concepts of AI Agents https://cloud.google.com/resources/core-concepts-ai-agents, accessed 18 July 2026